A power side-channel analysis method for lattice pqc

CN116707750BActive Publication Date: 2026-08-21NORTHWESTERN POLYTECHNICAL UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310561506.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-18
Publication Date
2026-08-21
Estimated Expiration
2043-05-18

AI Technical Summary

Benefits of technology

[0024] This invention proposes a power-based side-channel attack method for lattice-based PQC. Based on the relationship between sensitive information and power consumption, a side-channel attack template is established, enabling template attacks on various cryptographic algorithms. This invention employs a high-order plaintext (ciphertext) selection attack method, reducing the number of ciphertext entries required for side-channel analysis. By applying the proposed method to power-based side-channel analysis of Kyber512, the number of ciphertext entries required to recover the Kyber512 key is reduced by 58.48% compared to existing side-channel analysis methods. This invention's method can more effectively achieve side-channel attacks and security assessments on lattice-based post-quantum cryptographic cores.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116707750B_ABST
    Figure CN116707750B_ABST
Patent Text Reader

Abstract

The application discloses a power consumption side channel analysis method for a lattice PQC, establishes a side channel attack template based on the relationship between sensitive information and power consumption, combines sensitive information distribution characteristics, adopts a high-order selected plaintext (ciphertext) attack method to reduce the number of plaintexts (ciphertexts) used by side channel analysis, and realizes side channel attack and security evaluation on a lattice post-quantum cryptographic core. The method can more effectively realize side channel attack and security evaluation on the lattice post-quantum cryptographic core.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of security technology, specifically relating to a power consumption side-channel analysis method. Background Technology

[0002] Side-channel analysis (SSA) techniques exploit side-channel information leaked during the operation of cryptographic devices to crack keys. Common side-channel information includes time, power consumption, and electromagnetic parameters. This side-channel information is closely related to the encryption algorithm running on the device. By analyzing features related to sensitive information in the side-channel information, cryptanalysts can obtain details of the algorithm or key information. Compared to traditional mathematically based cryptanalysis methods, SSA is independent of or linearly related to key length, does not analyze the details of the cryptographic algorithm or low-level computational problems, and can recover the key with minimal effort, greatly improving the efficiency of cryptanalysis.

[0003] Power analysis is a typical attack method in side-channel analysis. Specifically, it leverages the different power consumption of signal '0' and signal '1' operations in cryptographic devices to crack keys by analyzing the power consumption information during device operation. Power analysis attack methods mainly include Simple Power Analysis (SPA), Differential Power Analysis (DPA), Correlation Power Analysis (CPA), and Template Attack (TA), with Template Attack being the most effective. Template Attack methods model the statistical characteristics of the random variable of power consumption trajectory and use discriminative methods to recover sensitive information from the power consumption trajectory. It mainly consists of two stages: template creation and template matching. Template Attack implementation requires first collecting power consumption trajectories from similar devices on the target device as known data to create a template. Then, the target device's power consumption trajectory is matched against the template to recover the key. If modeling is based on a sufficiently large number of power consumption trajectories, an attacker only needs one power consumption trajectory to recover sensitive information. Simultaneously, power side-channel analysis can be used to evaluate the security of cryptographic core implementations, which has important applications in the field of hardware security. Summary of the Invention

[0004] To overcome the shortcomings of existing technologies, this invention provides a power consumption side-channel analysis method for lattice-based PQC. Based on the relationship between sensitive information and power consumption, a side-channel attack template is established. Combining the distribution characteristics of sensitive information, a high-order plaintext (ciphertext) selection attack method is employed to reduce the number of plaintext (ciphertext) entries used in side-channel analysis, thereby achieving side-channel attacks and security assessments on lattice-based post-quantum cryptographic cores. This invention's method can more effectively achieve side-channel attacks and security assessments on lattice-based post-quantum cryptographic cores.

[0005] The technical solution adopted by this invention to solve its technical problem includes the following steps:

[0006] Step 1: Analyze the cryptographic algorithm and set the filtering conditions for selecting plaintext and ciphertext;

[0007] Step 2: Select plaintext or ciphertext that meets the set filtering conditions as input, and collect the power consumption of the cryptographic device in executing the key algorithm;

[0008] Step 3: Preprocess the collected power consumption trajectory data and vectorize the power consumption trajectory;

[0009] Step 4: Use the measurement leakage assessment method to select points in the power consumption trajectory that have a correlation with sensitive information greater than the set correlation threshold as points of interest, and add them to the corresponding attack template;

[0010] Step 5: Input plaintext or ciphertext that meets the set conditions into the target device, execute the cryptographic algorithm, and collect the corresponding power consumption trajectory;

[0011] Step 6: Perform data preprocessing on the power consumption trajectory of the target device, and select points with the same position as the template trajectory as points of interest to add to the target trajectory vector. Calculate the correlation between the target trajectory vector and the template trajectory vector. Templates with a correlation greater than a set threshold are candidate values ​​for sensitive information.

[0012] Step 7: Incorporate the results of each template matching into the sensitive information candidate value set, and combine them with the characteristics of sensitive information in the cryptographic algorithm. Use a higher-order plaintext or ciphertext selection method for analysis to reduce the number of plaintext or ciphertext used to crack sensitive information.

[0013] Step 8: Based on the cracked sensitive information and key generation algorithm, recover the initial key of the cryptographic algorithm.

[0014] Furthermore, the filtering condition in step 1 is to select plaintext or ciphertext that, after cryptographic transformation, is 0 for all bits except the target bit as input to the known device.

[0015] Furthermore, in step 2, an oscilloscope is used to collect the power consumption trajectory of the cryptographic device during operation.

[0016] Furthermore, step 3 specifically involves using statistical methods to preprocess the power consumption trajectory data to achieve power consumption trajectory vectorization.

[0017] Furthermore, the data preprocessing involves grouping the collected power consumption trajectories and taking their average values.

[0018] Furthermore, the attack template is an attack template for '0' and '1' created using the TVLA method.

[0019] Furthermore, in step 5, an oscilloscope is used to collect the power consumption trajectory of the target device during operation.

[0020] Furthermore, step 6 uses Euclidean distance to calculate the correlation between the target trajectory vector and the template trajectory vector.

[0021] Furthermore, in step 7, plaintext or ciphertext that meets the screening criteria is selected as input to the cryptographic device for side-channel analysis to narrow down the range of candidate values ​​for sensitive information; attack templates are established based on C or Python programming to realize cryptographic side-channel analysis.

[0022] Furthermore, step 8 utilizes the key generation algorithm in the target cipher to recover the initial key based on the cracked sensitive information.

[0023] The beneficial effects of this invention are as follows:

[0024] This invention proposes a power-based side-channel attack method for lattice-based PQC. Based on the relationship between sensitive information and power consumption, a side-channel attack template is established, enabling template attacks on various cryptographic algorithms. This invention employs a high-order plaintext (ciphertext) selection attack method, reducing the number of ciphertext entries required for side-channel analysis. By applying the proposed method to power-based side-channel analysis of Kyber512, the number of ciphertext entries required to recover the Kyber512 key is reduced by 58.48% compared to existing side-channel analysis methods. This invention's method can more effectively achieve side-channel attacks and security assessments on lattice-based post-quantum cryptographic cores. Attached Figure Description

[0025] Figure 1 This is a flowchart of the side-channel analysis method for lattice-based PQC.

[0026] Figure 2 This is a schematic diagram of collecting power consumption trajectories of known cryptographic devices.

[0027] Figure 3 This is a flowchart for establishing a template for a cryptographic algorithm side-channel attack.

[0028] Figure 4 This is a schematic diagram of the power consumption trajectory of the target device.

[0029] Figure 5 This is a flowchart of the side-channel analysis implementation.

[0030] Figure 6 This is the power consumption trajectory of the development board running Kyber512.

[0031] Figure 7 This is a diagram illustrating Kyber512's point of interest filtering.

[0032] Figure 8 This is a flowchart of a Kyber512 high-order chosen ciphertext attack.

[0033] Figure 9 This is a comparison of experimental results between Kyber512's attack scheme and existing attack schemes. Detailed Implementation

[0034] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0035] To address the security threats posed by quantum computing to traditional public-key cryptography, post-quantum cryptography (PQC) has gradually emerged as a new technology to replace existing public-key cryptography methods such as RSA and ECC. Although PQC's algorithm security is guaranteed by mathematical theory, the cryptographic core is susceptible to side-channel information leakage during hardware implementation, posing a serious threat to the security of PQC implementations. This invention aims to propose a power consumption side-channel analysis method for lattice-based PQC. Based on the relationship between sensitive information and power consumption, a side-channel attack template is established. Combining the distribution characteristics of sensitive information, a high-order plaintext (ciphertext) selection attack method is employed to reduce the number of plaintext (ciphertext) entries used in side-channel analysis, thereby enabling side-channel attacks and security assessment of lattice-based PQC cores.

[0036] This invention proposes a power consumption side-channel analysis method for lattice-based PQC, comprising the following steps:

[0037] Step 1: Analyze the cryptographic algorithm and set the filtering conditions for selecting plaintext (ciphertext) to make the device's power consumption more correlated with sensitive information, which will facilitate the subsequent template creation.

[0038] Step 2: Select plaintext (ciphertext) that meets the conditions as input, and collect the power consumption of the cryptographic device in executing the key algorithm;

[0039] Step 3: Preprocess the collected power consumption trajectory data and vectorize the power consumption trajectory;

[0040] Step 4: Use the measurement leakage assessment method to select points in the power consumption trajectory that are highly correlated with sensitive information as points of interest, and add them to the corresponding attack templates;

[0041] Step 5: Input the selected plaintext (ciphertext) that meets the conditions into the target device, execute the cryptographic algorithm, and collect the corresponding power consumption trajectory;

[0042] Step 6: Perform data preprocessing on the power consumption trajectory of the target device, and select points with the same position as the template trajectory as points of interest to add to the target trajectory vector. Calculate the correlation between the target trajectory vector and the template trajectory vector. Templates with high correlation are candidate values ​​for sensitive information.

[0043] Step 7: Incorporate the results of each template matching into the candidate value set, and combine them with the characteristics of sensitive information in the cryptographic algorithm. Use a higher-order plaintext (ciphertext) selection method for analysis to reduce the amount of plaintext (ciphertext) used to crack sensitive information.

[0044] Step 8: Based on the cracked sensitive information and key generation algorithm, recover the initial key of the cryptographic algorithm.

[0045] Furthermore, in step 1, the cryptographic algorithm is analyzed, the target transformation of the attack is determined, and a suitable plaintext (ciphertext) is selected to satisfy the higher correlation between the power consumption of the cryptographic operation and the target transformation. For example, plaintext (ciphertext) that is 0 except for the target bit after cryptographic transformation is selected as the input of the known device.

[0046] In step 2, select plaintext (ciphertext) that meets the conditions as input to the known cryptographic device, and use an oscilloscope to collect the power consumption trajectory of the cryptographic device during operation.

[0047] Step 3 involves using statistical methods to preprocess the power consumption trajectory data and vectorize the power consumption trajectory, such as grouping the collected power consumption trajectories and taking the average value.

[0048] Step 4 involves using a measurement leakage assessment method to select points in the power consumption trajectory that are highly correlated with sensitive information as points of interest, and then establishing attack templates for '0' and '1', such as the TVLA method.

[0049] Step 5 uses the plaintext (ciphertext) that meets the conditions as input to the target cryptographic device and uses an oscilloscope to collect the power consumption trajectory of the target device during operation.

[0050] Step 6 preprocesses the power consumption trajectory of the target device, selects points of interest at the same location as the attack template, and uses correlation calculation to match the attack template, such as Euclidean distance.

[0051] Step 7 uses a higher-order chosen plaintext (ciphertext) attack method to crack sensitive information. Combining the cracked sensitive information with the mathematical properties of the sensitive information itself, plaintext (ciphertext) that meets the screening conditions is selected as input to the cryptographic device for side-channel analysis, thereby narrowing down the range of candidate values ​​for sensitive information.

[0052] Step 8: Based on the cracked sensitive information, the initial key is recovered using the key generation algorithm in the target cipher.

[0053] This involves creating attack templates using C or Python programming languages ​​to perform cryptographic side-channel analysis.

[0054] The technical objective of this invention is to propose a power consumption side-channel analysis method for lattice-based PQC, enabling side-channel attacks and security assessments of lattice-based post-quantum cryptographic cores.

[0055] like Figure 1 The method of this invention involves three stages: side-channel attack template establishment, side-channel analysis implementation, and key recovery. The template establishment stage uses selected plaintext (ciphertext) as input to a known cryptographic device, collects and quantizes the power consumption trajectory of the cryptographic device during the execution of the cryptographic algorithm, and establishes a side-channel attack template. This mainly includes four modules: plaintext (ciphertext) selection, collection of known device power consumption, power consumption trajectory vectorization, and attack template establishment. The side-channel analysis implementation stage mainly includes two modules: collecting the target device's power consumption trajectory and implementing the side-channel attack. The power consumption trajectory of the target device is matched with the attack template to crack sensitive information. The key recovery stage is based on the key generation algorithm, using the sensitive information cracked through side-channel analysis to recover the initial key of the cryptographic algorithm.

[0056] Specifically, the steps include the following:

[0057] Step 1: Filter plaintext (ciphertext)

[0058] Analyze the characteristics of cryptographic algorithms to identify transformations related to sensitive information as target transformations. To improve the accuracy of attack templates, appropriate plaintext (ciphertext) can be selected based on the cryptographic algorithm to ensure that the power consumption during operation is highly correlated with the target transformation. For example, plaintext (ciphertext) that, after cryptographic transformation, is equal to 0 except for the target bit can be selected as the input to the known device.

[0059] Step 2: Collect the power consumption of known devices

[0060] During the template attack phase, the details of the cryptographic device's execution are known, and running the cryptographic algorithm is equivalent to white-box testing. The attacker, based on the principles of the cryptographic algorithm, determines the target transformation and selects appropriate plaintext (ciphertext) such that after the transformation, the sensitive information m related to the key is either '0' or '1'. After completing the ciphertext selection, the attacker uses a power consumption monitoring device, such as an oscilloscope, to collect the power consumption of the cryptographic device executing the target transformation, providing effective data support for establishing the attack template.

[0061] Step 3: Power consumption trajectory data preprocessing

[0062] Power consumption data collection is susceptible to external environmental interference, resulting in power consumption trajectories containing noise such as Gaussian noise. Therefore, it is necessary to preprocess the collected power consumption trajectories using an averaging method before vectorizing them to facilitate subsequent attack template creation. To improve the quality of power consumption trajectories, they can be grouped before preprocessing to reduce the impact of noise on their accuracy.

[0063] Step 4: Create a side-channel attack template

[0064] The collected power consumption trajectory consists of a set of trajectory points. Direct analysis using these trajectory points results in a large number of invalid points, meaning these points have low relevance to sensitive information. The method proposed in this invention first uses a leakage assessment method to filter the trajectory points, selecting those with high relevance to key information as points of interest (POIs) and adding them to the template trajectory. Based on the selected POIs, templates with m=0 and m=1 are established respectively.

[0065] Step 5: Collect power consumption data of the target cryptographic device

[0066] The selected plaintext (ciphertext) is used as input to the target device, and encryption (decryption) operations are performed on the target device. The power consumption of the target device during operation is collected. In this step, the cryptographic device serving as the attack target is equivalent to black-box testing, and the collected power consumption trajectory serves as the experimental dataset for template attacks.

[0067] Step 6: Match the target device's power consumption trajectory with the attack template trajectory

[0068] The power consumption trajectory of the target device is preprocessed to reduce trajectory noise. Then, interest points at the same locations as the attack template are selected for template matching. The correlation between the power consumption trajectory of the target device and the template trajectory can be obtained by calculating the Euclidean distance between them. Templates with high correlation are selected as candidate values ​​for sensitive information.

[0069] Step 7: Implement a high-order chosen plaintext (ciphertext) attack

[0070] By combining candidate values ​​obtained from template matching, plaintext (ciphertext) is selected based on the characteristics of the sensitive information distribution to carry out side-channel attacks. Specifically, high-order plaintext (ciphertext) is used for analysis, and the results of each attack analysis are incorporated into the candidate value set. Compared with analysis methods that use random ciphertext without a strategy, this reduces the number of ciphertexts required to crack sensitive information.

[0071] Step 8: Key Recovery

[0072] Based on the key generation algorithm, the initial key of the cryptographic algorithm is recovered using the sensitive information cracked in step 7.

[0073] The Kyber512 encryption algorithm is used as an example to illustrate the side-channel attack method proposed in this invention.

[0074] The hardware environment used for implementation included an Intel i7 processor, a general-purpose device for collecting power consumption information, and a Sakura-x development board. During the template setup phase, the Sakura-x development board was considered a known device; during the attack phase, it became the target device. We implemented the proposed method for the Kyber512 using C and Python languages.

[0075] 1) Collect power consumption traces of the Sakura-x development board running the Kyber512 algorithm.

[0076] Based on the principles of cryptographic algorithms, the target is determined to be transformed into a hash algorithm G, and ciphertext T that meets the conditions is selected. The Kyber512 encryption algorithm is downloaded to the development board, the decryption function of the Kyber512 key negotiation algorithm is run, and the power consumption trajectory of the Kyber512 algorithm is collected using a general-purpose oscilloscope, such as... Figure 6 As shown, gray represents power consumption, and black represents the target transformation trigger signal.

[0077] 2) Establish a side-channel attack template

[0078] The power consumption trajectories are grouped, and the average of each group's power consumption trajectories is taken for data preprocessing. The TVLA method is used to filter the trajectory points, selecting those with high relevance to sensitive information as points of interest and adding them to the template. For example... Figure 7 As shown, the TVLA method is used to calculate the difference between the two sets of data m=0 and m=1. A threshold of 3 is set, and points with TVLA values ​​greater than 3 or less than -3 are selected as points of interest. Templates for m=0 and m=1 are then established based on the selected points of interest. The power consumption of the Sakura-x development board executing the cryptographic algorithm is also measured.

[0079] Select the ciphertext T as input data, run the Kyber512 algorithm on the Sakura-x development board, and use a general-purpose oscilloscope to collect the corresponding power consumption trajectory. Perform data preprocessing on the collected power consumption trajectory, and select points at the same locations as the interest points of the template trajectory selected in step 2) as the interest points of the target device's attack power consumption trajectory.

[0080] 3) Recover the initial key of the cryptographic algorithm

[0081] The power consumption trajectory of the target device is matched with the template trajectory. The power consumption side-channel analysis method of high-order selected ciphertext is used to recover all coefficients of the polynomial s related to sensitive information in the Kyber512 algorithm, and then the Kyber512 private key sk and shared key K are cracked.

[0082] Traditional template matching methods require analyzing the power consumption trajectories of 2η+1 ciphertexts (where η is a parameter of the Kyber algorithm, and the coefficients of the polynomial s in the Kyber algorithm range from -η to η) to crack the coefficients of the polynomial s. Each coefficient of the polynomial s in the Kyber algorithm is determined by the central binomial distribution function (CBD). ηIn the Kyber512 algorithm, parameter η = 3. Assuming template matching is completed after selecting η ciphertext power trajectories, if the coefficients of polynomial s are unique, the attack is successful. If the coefficients of polynomial s are not unique, the range of s can be narrowed down to N candidate value sets, where the order of each candidate value set is represented by n. i This means that each set needs to be analyzed at most n more times. i - Only one ciphertext is needed to determine the key information. Using a higher-order ciphertext selection method can significantly reduce the number of ciphertexts required for an attack. Based on the higher-order ciphertext selection attack method proposed in this invention, the ciphertext is selected again during attack analysis, taking into account the characteristics of the ciphertext and the coefficient distribution characteristics of the polynomial s. This narrows down the range of candidate values ​​for the coefficients of the polynomial s. The selection of ciphertext continuously reduces the candidate values ​​until a unique candidate value is selected. The specific process is as follows: Figure 8 As shown.

[0083] In CPAPKE.KeyGen(), the polynomial s undergoes relevant encoding transformations to generate the private key sk. The relevant encoding functions and parameters are known. Therefore, after cracking the coefficients of the polynomial s, the private key sk can be cracked. After obtaining sk, the shared key K can also be obtained by using the relevant known transformations in Kyber.CCAKEM.Dec().

[0084] 4) Analysis of experimental results

[0085] Traditional Kyber512 side-channel attack methods require 7 ciphertexts to recover a single position of polynomial s, while the method proposed in this invention requires an average of only 2.906 ciphertexts. Figure 9 As shown, to attack all positions of polynomial s, traditional methods require selecting 3584 ciphertexts, while the high-order ciphertext selection attack method proposed in this invention only requires 1488 ciphertexts, reducing the requirement by 58.48%.

Claims

1. A power consumption side-channel analysis method for lattice-based PQC, characterized in that, Includes the following steps: Step 1: Analyze the cryptographic algorithm and set the filtering conditions for selecting plaintext and ciphertext; Step 2: Select plaintext or ciphertext that meets the set filtering conditions as input, and collect the power consumption of the cryptographic device in executing the key algorithm; Step 3: Preprocess the collected power consumption trajectory data and vectorize the power consumption trajectory; Step 4: Use the measurement leakage assessment method to select points in the power consumption trajectory whose correlation with sensitive information is greater than the set correlation threshold as points of interest, and add them to the corresponding attack templates; the attack templates are attack templates for '0' and '1' established using the TVLA method; Step 5: Input plaintext or ciphertext that meets the set conditions into the target device, execute the cryptographic algorithm, and collect the corresponding power consumption trajectory; Step 6: Perform data preprocessing on the power consumption trajectory of the target device, and select points with the same position as the template trajectory as points of interest to add to the target trajectory vector. Calculate the correlation between the target trajectory vector and the template trajectory vector. Templates with a correlation greater than a set threshold are candidate values ​​for sensitive information. Step 7: Incorporate the results of each template matching into the sensitive information candidate value set, and combine this with the characteristics of sensitive information in the cryptographic algorithm. Analyze using a higher-order plaintext or ciphertext selection method to reduce the number of plaintext or ciphertexts used to crack sensitive information. The higher-order ciphertext selection attack method, combining ciphertext characteristics and the coefficient distribution of the polynomial, selects ciphertext again during attack analysis, narrowing the candidate value range of the polynomial coefficients. This selection process continuously narrows the candidate values ​​until a unique candidate value is chosen. Plaintext or ciphertext that meets the filtering criteria is selected as input to the cryptographic device for side-channel analysis, further narrowing the candidate value range for sensitive information. An attack template is created using C or Python programming to implement cryptographic side-channel analysis. Step 8: Based on the cracked sensitive information and key generation algorithm, recover the initial key of the cryptographic algorithm; based on the cracked sensitive information, use the key generation algorithm in the target cryptography to recover the initial key.

2. The power consumption side-channel analysis method for lattice-based PQC according to claim 1, characterized in that, The filtering condition in step 1 is to select plaintext or ciphertext that, after cryptographic transformation, is 0 for all bits except the target bit as input to the known device.

3. The power consumption side-channel analysis method for lattice-based PQC according to claim 1, characterized in that, In step 2, an oscilloscope is used to collect the power consumption trajectory of the cryptographic device during operation.

4. The power consumption side-channel analysis method for lattice-based PQC according to claim 1, characterized in that, Step 3 specifically involves using statistical methods to preprocess the power consumption trajectory data, thereby vectorizing the power consumption trajectory.

5. The power consumption side-channel analysis method for lattice-based PQC according to claim 1, characterized in that, The data preprocessing involves grouping the collected power consumption trajectories and taking the average value.

6. The power consumption side-channel analysis method for lattice-based PQC according to claim 1, characterized in that, In step 5, an oscilloscope is used to collect the power consumption trajectory of the target device during operation.

7. The power consumption side-channel analysis method for lattice-based PQC according to claim 1, characterized in that, Step 6 uses Euclidean distance to calculate the correlation between the target trajectory vector and the template trajectory vector.

Citation Information

Patent Citations

  • Side channel attack method for SM2 public key cryptography encryption algorithm

    CN104780051A

  • Verifiable decryption method based on MLWE and MSIS

    CN115150094A